This website uses cookies

Read our Privacy policy and Terms of use for more information.

The views expressed here are solely my own. They do not represent the opinions, positions, or policies of any current or former employer, client, or affiliated organization.

A few days ago, Norman Valdez (Director of Technology and Design at CERIC, and someone deeply embedded in Toronto's AI governance community) published a reflection on what it takes to align AI with the public interest. Most of it operates at the level of principles: individuals need boundaries, organizations need policy, sectors need coordination.

But one case study in the piece stopped me, because it wasn't abstract at all.

Table of Contents

The case that matters

In June 2026, two major earthquakes hit Venezuela. Within days, independent developers (inside the country and across the diaspora) had built platforms to help: locating missing people, mapping hospital capacity, coordinating aid, tracking shelters. One platform reportedly went from zero to over 30,000 missing-person reports in 48 hours. People used tools like Replit and Claude to build in hours what might once have taken weeks.

It's a genuinely moving example of what's possible when technical skill meets urgency.

It's also, if you look at it from where I sit (content operations and governance) a case study in exactly the kind of failure mode I deal with professionally, just compressed into 72 hours instead of unfolding over quarters. Multiple registries collecting the same kind of data with no shared schema. Divergent counts of missing people that differed by tens of thousands, not because anyone lied, but because there was no agreed way to reconcile records across systems. Sensitive personal data (names, addresses, photos, family relationships) collected before anyone had time to think about consent, retention, or what happens to that data once the crisis ends.

Norman names this well: the problem isn't that people acted. It's that we expect coordination to emerge spontaneously, after the crisis has already started. Then he asks the question that matters most, and leaves it open: how do you build the communities capable of aligning AI with the public interest, when the actors involved didn't exist until the emergency did?

I don't think that question has a clean answer. But I think it has a more specific answer than "build community", because I think the fix isn't primarily about the people. It's about where you place the control.

Why governance-by-policy doesn't reach this case

Every content and data governance framework I've worked with (the kind Norman himself built at CERIC) shares one assumption: you know who's building, under what mandate, with what oversight, before they build. A policy, a procurement checklist, a review process, all of it depends on there being an accountable party to hand the policy to.

The Venezuela case breaks that assumption completely. There is no organization to govern. There's a developer in Caracas and another in Miami, neither one waiting for anyone's permission, both acting in good faith, both potentially about to collect and expose sensitive data about vulnerable people with zero guardrails, not because they're careless, but because nobody handed them any, and there was no time to look for some.

You cannot govern people who don't exist until the event does. But you can govern the surface they build on.

Standby governance: an open idea, not a solution

Here's what I keep coming back to, and I want to be upfront that this is a conversation-starter, not a polished proposal, there's a lot to work out.

The Venezuela responders didn't build from scratch in a vacuum. They used existing platforms: Replit, and others like it. Those platforms are commercial entities with clear ownership, infrastructure, and (this matters) a business incentive to be associated with visible, high-trust humanitarian outcomes.

What if that commercial incentive could be pointed at exactly this problem?

Picture a "dormant" emergency mode that a platform like Replit could maintain, inactive until a verified disaster-alert feed (something like GDACS or USGS earthquake alerts) confirms a major event is underway. Once triggered, users building anything disaster-related would be offered a fork of a pre-built starter kit, not a generic template, but one that already contains:

  • A shared data schema for the type of crisis (missing-person records, shelter capacity, aid coordination), so ten independent apps produce reconcilable data instead of ten incompatible ones

  • A tiered verification flow already built in (self-reported > second-source confirmed > official), instead of every developer inventing their own under pressure

  • Default rules for sensitive data retention and deletion, decided in advance rather than at 3 a.m. on day one

  • A shared reporting layer that feeds a central deduplication ledger, so families aren't checking five different databases with five different answers

And the platform would have a reason to want people to use it: credibility. A "verified" mark on your emergency app (because it inherited guardrails a coalition of humanitarian and policy organizations helped define) is worth more, in that moment, than building faster with none.

None of this works, though, without limits designed against gaming it. A benefit like this can't be exploitable for commercial advantage; it would need to be restricted to non-commercial, listed-in-the-emergency-hub use, reviewed after the fact, tied to actual public benefit rather than platform PR. Those constraints are exactly the kind of thing that would need to be worked out with the platforms, hosting, data residency, and liability all look different depending on who's providing the infrastructure. I don't have that answer. I don't think anyone does yet.

What I'm more confident about is where the standard itself should come from: not any single platform unilaterally, which would look self-interested, but a pre-negotiated coalition (the kind of body Norman describes at the sectoral level, groups like the Center for AI and Digital Policy working alongside humanitarian organizations) defining the schema once, so that Replit, or whichever platform, simply implements it as their dormant service.

The layer that's missing

Norman's framework moves from individual, to organizational, to community, to sectoral, to public interest. It's a good map. What I'd add is a layer underneath all of it: the tooling layer, the actual surface where the next Desaparecidos Terremoto Venezuela gets built, in an afternoon, by someone who has never heard of AI governance and doesn't need to.

You can't legislate that person's judgment in advance. But you can make sure that when they open a blank project at the worst possible moment, the fastest path forward is already the responsible one.

That's not a finished framework. It's an invitation to build one, and I'd genuinely like to hear from people closer to the platform side, and to Norman's network, about what's missing from it.

Juan Carlos Vásquez has spent ten years inside enterprise content operations, repairing content supply chains before scaling them. Fix to Flow is the discipline that work produced. The views here are his own.

Keep Reading